Effective September 24, 2026. Version 2026-09-24.
First version for this product.
This Privacy Policy covers howdybell.com, the HowdyBell web app, and the HowdyBell web chat widget (the Service, we, us, our). HowdyBell is owned and operated by Gossip Apps LLC, a Texas limited liability company. For your own account data, such as your login email and name, HowdyBell is the controller. For the data about your own contacts and customers that you and your team put into the Service (Customer Data), you are the controller and HowdyBell is the processor, acting on your instructions; see Section 15.
| Category | What |
|---|---|
| Account | Email address, name, and workspace name, created when you sign up. |
| Content you provide | Contacts, pipeline stages, tasks, notes, canned replies, CSV imports, and conversation messages and attachments. This is Customer Data; you control it. |
| Payment | Not collected yet. HowdyBell has no paid plans as of this Effective Date. When paid plans launch, Stripe will process payments and we will receive only the last four digits of the card, the card brand, billing country, and receipts. |
| Usage and device data | IP address, browser user agent, pages visited, timestamps, and error and crash logs. |
| Communications | Support emails you send to [email protected]. |
| Cookies and similar | See Section 11. |
| Information from third parties | Delivery and read status for messages you send through Twilio (SMS, WhatsApp) and Meta (Messenger, Instagram). |
If you are in the EEA or UK, we process personal data under these legal bases: performance of a contract with you, our legitimate interests in keeping the Service secure and improving it, your consent for marketing messages and non-essential cookies, and compliance with a legal obligation.
| Processor | Purpose |
|---|---|
| DigitalOcean | Hosting, United States |
| Cloudflare | CDN, DNS, and DDoS protection |
| Resend | Sending email from the Service |
| Twilio | Sending and receiving SMS and WhatsApp messages |
| Meta | Sending and receiving Facebook Messenger and Instagram messages |
| Stripe | Payments, once paid plans launch |
We also share data with law enforcement or in response to a valid legal request, in a business transfer such as a merger or sale, and wherever you direct us to. We do not sell personal information and we do not share it for cross-context behavioral advertising.
We use TLS to encrypt data in transit and encryption at rest on our hosting volumes. Access to production systems is limited to the people who operate HowdyBell. We manage secrets and credentials separately from application code and take regular backups. No method of storage or transmission is perfectly secure. If a breach occurs that requires notice under Texas Business and Commerce Code 521.053 or other applicable law, we will notify affected parties as the law requires.
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, and to restrict or object to how we use it.
California residents (CCPA/CPRA) have the right to know what we collect, delete it, correct it, opt out of sale or sharing, limit use of sensitive data, and not be discriminated against for exercising these rights. You may use an authorized agent to make a request, and we will verify your identity before acting on it.
Texas residents (Texas Data Privacy and Security Act) have the right to access, correct, delete, and receive a portable copy of their data, and to opt out of targeted advertising, sale, or profiling. If we decline a request, you can appeal by writing to [email protected]; we respond to an appeal within 60 days, and you can then complain to the Texas Attorney General.
If you are in the EEA or UK, you have the rights above plus the right to complain to your local supervisory authority.
To exercise any of these rights, write to [email protected]. We respond within 45 days and may ask you to verify your identity first.
The Service is not directed to children. We do not allow anyone under 18 to hold an account and we do not knowingly collect personal information from anyone under 13. If we learn otherwise, we delete the account and its data.
We store data in the United States. Where EEA or UK data passes through a processor outside those regions, we rely on standard contractual clauses as required.
| Name | Set by | Purpose |
|---|---|---|
| hb_session | howdybell.com | Keeps you signed in. HttpOnly, cannot be read by page scripts. Expires after 30 days. |
| lgw_token_* | The HowdyBell web chat widget, on the site where it is installed | Local storage, not a cookie. Remembers a visitor's own conversation token so they can return to it. |
| lgw_started_* | Same widget | Local storage. Remembers whether that visitor already started a conversation. |
| lgw_seen_* | Same widget | Local storage. Remembers which messages that visitor has already seen. |
| lgw_who_* | Same widget | Local storage. Remembers the name a returning visitor already gave. |
We do not use any third-party analytics or advertising cookies. We honor Global Privacy Control signals as an opt-out where the law requires one, though we do not currently sell or share personal information in a way that requires it.
Browsers' Do Not Track signal is not a standard the industry has agreed on, so we do not currently respond to it. We honor Global Privacy Control as described in Section 11.
If we make a material change to this Privacy Policy, we notify you the same way described in Section 5 of the Terms, at least 14 days before it takes effect, except where the law or a new feature requires an earlier change.
HowdyBell. [email protected].
The contacts, conversations, tasks, and other records you and your team put into HowdyBell belong to you. You are the controller of that data and HowdyBell is the processor, acting only on your written instructions, which these Terms and this Policy count as. We process it for one purpose: to provide, secure, and support the Service. We do not use it for our own marketing, we do not use it to train AI models, and we do not sell it.
We use the sub-processors listed in Section 5 to run the Service, and we hold them to the same duties under our own agreements with them.
If your account is terminated, we delete your Customer Data within 30 days, except for the narrow records the law makes us keep longer (Section 6). If we learn of a security incident that puts your Customer Data at risk, we tell you without undue delay so you can meet your own notice duties to your customers.